Jingle Thief Targets Cloud Environments for Gift Card Fraud
Summary
Hide ▲
Show ▼
Jingle Thief, a cybercriminal group, exploits cloud environments in the retail and consumer services sectors to steal and issue unauthorized gift cards. The group uses phishing and smishing to steal credentials and maintain access for extended periods, often over a year. They target gift card issuance applications to issue high-value cards, leveraging cloud infrastructure to impersonate legitimate users and evade detection. The group is believed to be active since late 2021 and has been linked to criminal groups Atlas Lion and Storm-0539. Their activities coincide with festive seasons and holiday periods, making gift card fraud a lucrative choice due to its ease of redemption and difficulty in tracing. In April and May 2025, Jingle Thief launched a wave of coordinated attacks targeting global enterprises, maintaining access for about 10 months and compromising 60 user accounts within a single organization.
Timeline
-
23.10.2025 10:52 1 articles · 8h ago
Jingle Thief Launches Coordinated Attacks on Global Enterprises
In April and May 2025, Jingle Thief launched a wave of coordinated attacks targeting global enterprises. The group used phishing attacks to obtain credentials necessary to breach victims' cloud infrastructure. In one campaign, the attackers maintained access for about 10 months and compromised 60 user accounts within a single organization. The attacks involved accessing gift card issuance applications to issue high-value cards while minimizing logs and forensic trails.
Show sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
Information Snippets
-
Jingle Thief targets cloud environments in the retail and consumer services sectors for gift card fraud.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
-
The group uses phishing and smishing to steal credentials and gain unauthorized access to cloud infrastructure.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
-
Jingle Thief maintains access for extended periods, often over a year, to conduct extensive reconnaissance and evade detection.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
-
The group targets gift card issuance applications to issue high-value cards, leveraging cloud infrastructure to impersonate legitimate users.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
-
Jingle Thief is believed to be active since late 2021 and has been linked to criminal groups Atlas Lion and Storm-0539.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
-
The group's activities coincide with festive seasons and holiday periods, making gift card fraud a lucrative choice.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52
-
In April and May 2025, Jingle Thief launched a wave of coordinated attacks targeting global enterprises, maintaining access for about 10 months and compromising 60 user accounts within a single organization.
First reported: 23.10.2025 10:521 source, 1 articleShow sources
- “Jingle Thief” Hackers Exploit Cloud Infrastructure to Steal Millions in Gift Cards — thehackernews.com — 23.10.2025 10:52